A role-based training deck plus the attendance and acknowledgement register that turns completion into evidence.
What is in the download
- Format: PPTX + XLSX
- Length: 42 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the template
The deck is structured as a common core plus role modules, mirroring how the requirement itself splits: §164.308(a)(5) requires security awareness training for the entire workforce, while §164.530(b) requires privacy training relevant to each person’s function. The core covers what PHI and ePHI are, the permitted-use basics, phishing and social engineering recognition, password and device hygiene, how to report a suspected incident (and that reporting is expected, not punished), and what the sanction policy means. The role modules add the function-specific layer: a clinical module (verification, minimum necessary at the point of care), an administrative and billing module (permitted disclosures versus authorisation-required ones), and a technical module for engineers (ePHI in logs, test data, and vendor channels). Each slide carries speaker notes with the regulatory citation behind the point being made.
The XLSX is the half that makes the training defensible: a register recording person, role, course version, date, and quiz score, plus a short assessment bank and a roster-reconciliation tab that compares completions against your full workforce list — contractors and temps included, since they are workforce members when they act under your direct control.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
For a training deck, step two means removing slides describing controls and procedures you do not run — training people on an incident hotline that does not exist manufactures confusion and evidence against you in one move.
How to customise it
Replace the generic examples with your own systems and stories: the phishing slide should show the kind of email your staff actually receive, the reporting slide should name your real channel and your real Security Officer, and the policy references should point at your adapted policy set by document name and version. Cut the role modules you do not need and split ones that lump too much together. Set the version number on the title slide and increment it whenever content materially changes — the register records completions against versions, and “trained in 2025” only means something if you can show what the 2025 course contained. Finally, decide the delivery mechanics: live sessions recorded in the register, or self-serve slides with the quiz as the completion gate. Both work; undocumented hallway training does not.
Common mistakes
- Training before defining. Running the deck before your policies are adapted means training people on documents that are about to change, then re-training them.
- The payroll denominator. A 100% completion rate calculated against employees only, while contractors with production access were never enrolled, is a finding wearing a green dashboard.
- No new-hire gate. Training “within the first quarter” leaves untrained people handling PHI for months. Tie completion to system access.
- Attendance without assessment. A sign-in sheet proves presence; a scored quiz proves comprehension. Reviewers increasingly expect the latter.
- One deck forever. Threats and systems change yearly; a 2023 deck delivered unmodified in 2026 documents that the programme is a ritual.
Related templates
Training operationalises the rest of the library — it is where the incident response plan, the password policy, and the remote work policy reach actual behaviour. The annual review checklist includes the yearly roster reconciliation, and the training guide covers frequency, records, and role-based design in depth.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.